CIPL’s response commends the ANPD for a thoughtful, evidence-informed, and risk-based draft. In particular, we welcome:
• the recognition that age verification “is not an end in itself” but rather one pillar of a broader protective ecosystem;
• the structuring of the framework around proportionality and a risk taxonomy;
• the clear preference for privacy-preserving methods, including verifiable credentials, age tokens, double-blind architectures, and zero-knowledge proofs; and
• the emphasis on interoperability and data minimization.
These positions are aligned with CIPL’s extensive body of work on children’s data privacy and age assurance.
We also encourage the agency to ensure that the Guidelines’ advisory character is reflected consistently throughout. We specifically ask for the Guidelines to distinguish, where relevant, between best-practice recommendations and legal obligations.
CIPL also recommends further refinement of the Guidelines’ risk taxonomy, including more granular examples for moderate-risk services and avoiding the automatic classification of all 18+ services as high risk without a contextual assessment.
We also ask for clarification on how age-assurance impact assessments interact with other assessment requirements under Brazilian law , and we encourage the ANPD to avoid duplicative compliance obligations across app stores, operating systems, and service providers.